<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:35:16 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:4751 — Moderate: httpd:2.4 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:4751</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mod_md&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: mod_http2 (1.15.7). (BZ#1814236)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: memory corruption on early pushes (CVE-2019-10081)&lt;/p&gt;
&lt;p&gt;* httpd: read-after-free in h2 connection shutdown (CVE-2019-10082)&lt;/p&gt;
&lt;p&gt;* httpd: null-pointer dereference in mod_remoteip (CVE-2019-10097)&lt;/p&gt;
&lt;p&gt;* httpd: mod_rewrite configurations vulnerable to open redirect (CVE-2020-1927)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: DoS via slow, unneeded request bodies (CVE-2018-17189)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: read-after-free on a string compare (CVE-2019-0196)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: possible crash on late upgrade (CVE-2019-0197)&lt;/p&gt;
&lt;p&gt;* httpd: limited cross-site scripting in mod_proxy error page (CVE-2019-10092)&lt;/p&gt;
&lt;p&gt;* httpd: mod_rewrite potential open redirect (CVE-2019-10098)&lt;/p&gt;
&lt;p&gt;* httpd: mod_proxy_ftp use of uninitialized value (CVE-2020-1934)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mod_md&lt;/p&gt;
&lt;p&gt;The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: mod_http2 (1.15.7). (BZ#1814236)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* httpd: memory corruption on early pushes (CVE-2019-10081)&lt;/p&gt;
&lt;p&gt;* httpd: read-after-free in h2 connection shutdown (CVE-2019-10082)&lt;/p&gt;
&lt;p&gt;* httpd: null-pointer dereference in mod_remoteip (CVE-2019-10097)&lt;/p&gt;
&lt;p&gt;* httpd: mod_rewrite configurations vulnerable to open redirect (CVE-2020-1927)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: DoS via slow, unneeded request bodies (CVE-2018-17189)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: read-after-free on a string compare (CVE-2019-0196)&lt;/p&gt;
&lt;p&gt;* httpd: mod_http2: possible crash on late upgrade (CVE-2019-0197)&lt;/p&gt;
&lt;p&gt;* httpd: limited cross-site scripting in mod_proxy error page (CVE-2019-10092)&lt;/p&gt;
&lt;p&gt;* httpd: mod_rewrite potential open redirect (CVE-2019-10098)&lt;/p&gt;
&lt;p&gt;* httpd: mod_proxy_ftp use of uninitialized value (CVE-2020-1934)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:4751</guid>
    </item>
    <item>
      <title>bdu:2019-02559</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-02559</link>
      <description>bdu:2019-02559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-02559</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2019-0196 — CVE-2019-0196 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-0196</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-0196</guid>
    </item>
    <item>
      <title>certfr-2019-avi-141 — De multiples vulnérabilités ont été découvertes dans Apache Httpd.
Certaines d'entre elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-141</link>
      <description>certfr-2019-avi-141</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-141</guid>
    </item>
    <item>
      <title>cnvd-2019-08942</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-08942</link>
      <description>cnvd-2019-08942</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-08942</guid>
    </item>
    <item>
      <title>EUVD-2026-48362</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-48362</link>
      <description>EUVD-2026-48362</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-48362</guid>
    </item>
    <item>
      <title>fkie_cve-2019-0196</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-0196</link>
      <description>&lt;p&gt;A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-0196</guid>
    </item>
    <item>
      <title>GHSA-vqc7-p7p7-97wf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vqc7-p7p7-97wf</link>
      <description>&lt;p&gt;A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vqc7-p7p7-97wf</guid>
    </item>
    <item>
      <title>gsd-2019-0196</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-0196</link>
      <description>gsd-2019-0196</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-0196</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:1209-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1209-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:1209-1</guid>
    </item>
    <item>
      <title>RHSA-2019:3932 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Security Release on RHEL 6</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:3932</link>
      <description>&lt;p&gt;openssl: timing side channel attack in the DSA signature algorithm openssl: RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.c allows attackers to recover private keys openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) httpd: mod_http2: DoS via slow, unneeded request bodies httpd: mod_session_cookie does not respect expiry time httpd: mod_http2: read-after-free on a string compare httpd: mod_http2: possible crash on late upgrade httpd: mod_auth_digest: access control bypass due to race condition HTTP/2: large amount of data requests leads to denial of service HTTP/2: flood using PRIORITY frames results in excessive resource consumption HTTP/2: 0-length headers lead to denial of service HTTP/2: request for large response leads to denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: timing side channel attack in the DSA signature algorithm openssl: RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.c allows attackers to recover private keys openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) httpd: mod_http2: DoS via slow, unneeded request bodies httpd: mod_session_cookie does not respect expiry time httpd: mod_http2: read-after-free on a string compare httpd: mod_http2: possible crash on late upgrade httpd: mod_auth_digest: access control bypass due to race condition HTTP/2: large amount of data requests leads to denial of service HTTP/2: flood using PRIORITY frames results in excessive resource consumption HTTP/2: 0-length headers lead to denial of service HTTP/2: request for large response leads to denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:3932</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:0873-1 — Security update for apache2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:0873-1</link>
      <description>&lt;p&gt;Security update for apache2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:0873-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-0196</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0196</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: apache2&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0196</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2047 — Apache HTTP Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2047</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen im Apache HTTP Server ausnutzen, um seine Rechte zu erweitern, Sicherheitsrestriktionen zu umgehen oder um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen im Apache HTTP Server ausnutzen, um seine Rechte zu erweitern, Sicherheitsrestriktionen zu umgehen oder um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2047</guid>
    </item>
  </channel>
</rss>
